Cyberattacks against water and wastewater systems reportedly have reached at least a dozen states, with threat actors exploiting low-complexity attacks against industrial controllers. The intrusions, possibly linked to the Iranian government, prove the US’s water infrastructure remains dangerously exposed.
In recent weeks, water and wastewater organizations associated with a number of different US states have disclosed cyberattacks against their systems. Minnesota was the first to confirm such attacks late last month, saying that cyberattackers targeted operational technology (OT) systems for more than 30 water systems. Around the same time on July 30, the Cybersecurity and Infrastructure Security Agency (CISA) updated an earlier advisory warning of “a significant increase in cyber-threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector.”
The US cyber agency said threat actors were modifying PLC passwords to lock out operators and also disconnecting PLCs by changing their IP addresses. “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the Internet as soon as possible,” CISA said at the time.
This CISA advisory followed the FBI updating an April warning on July 22 that Iranian threat actors are targeting PLCs in critical infrastructure manufactured by Rockwell Automation/Allen Bradley, Schneider Electric, Siemens, and possibly other vendors.
It’s not just Minnesota. Relevant municipal and local water officials from Georgia, Michigan, and South Dakota have also suffered attacks that appear to be connected with this wider campaign. And in recent days, Alabama and New Jersey communities have similarly confirmed attacks.
Modernize to Stem the Flow of Water Sector Disruptions
So far there’s been no disruption to the water supply, and these PLC attacks appear to be intended to stoke fear rather than carry out permanent damage or extortion, at least to public knowledge.
That’s not to say there’s not disruption happening. Some of the attacks to date, such as the ones in Minnesota, involved locking local operators out of PLCs while disrupting visibility and control functions, forcing operators to use manual workarounds. South Dakota and Michigan-targeted attacks appeared to be consistent with this. The most severe activity known to date involved Georgia, where cyber activity against Clayton County reportedly caused a water pressure drop and forced the agency to issue a boil water advisory.
John Gallagher, vice president at OT and IoT security firm Viakoo, says industrial controllers like PLCs were historically engineered for physical isolation and reliability rather than Internet exposure, meaning that many lack basic secure-by-design capabilities like multifactor authentication (MFA) or encrypted communication.
“Like many OT and Internet of Things (IoT) systems, they may have built-in networking that is turned on by default unless it is disabled during installation,” he tells Dark Reading. “This is compounded by maintenance which often is done by non-IT staff; field technicians and third-party integrators frequently install cellular modems, satellite links, or direct port forwards to allow remote troubleshooting without notifying central IT/OT teams.”
Markus Mueller, field CISO at Nozomi Networks, similarly says that PLCs are common targets because of the reality behind how the water and wastewater industry operates.
“There are roughly 170,000 drinking water and wastewater systems, and most are small, decentralized, and running OT that was installed by a third party,” he explains. “Cyber awareness and capabilities are limited at these utilities. There is an operational need for these devices to be connected, but there’s also a lack of funding, mandate, or awareness to keep them secure. It is unfortunate, as there are plenty of good people in the water industry who work hard to deliver clear, reliable water, but they are not cyber people. And even if they are aware of the issue, they often can’t get the budget or resources to set up these systems properly.”
Is Iran Turning on the Utility Cyberattack Taps?
While there has been no definitive attribution as to who’s behind the offensive, one possible culprit is the pro-Iran CyberAv3ngers hacktivist group, which has hit US water infrastructure before, according to a CISA alert from 2023 and 2024.
Researchers have previously called the group opportunistic and propagandistic in nature, leaning on lower stakes attacks to stoke public fear and gain media attention. Attacks like this are closer to hacktivism in nature — as if the threat actor is trying to say, “We can get to you.”
That said, several cybersecurity firms and researchers have noted similarities between the recent PLC-targeting campaign and previous operations attributed to the Iranian Revolutionary Guard Corps (IRGC) and/or the IRGC-linked CyberAv3ngers group, though federal authorities have not publicly attributed the latest multistate water-sector intrusions to either.
Mueller tells Dark Reading that a lack of sophistication in tradecraft does not necessarily mean the adversary is not capable of more.
“Adversaries will deploy the tactics, techniques, and procedures (TTPs) that are needed to meet the objective they have,” he says. “The scale and coordination required for this campaign point to a well-organized adversary that likely is technically capable of more. Based on this, I assess with moderate confidence that the adversary is focused on a widespread disruption and causing pain to operators and responders. In a lot of ways, this aligns with the hacktivist playbook we have seen, but the missing component is the claims of responsibility and, frankly, the marketing from the adversary.”


